首页> 外文会议>IEEE Conference on Communications and Network Security >ACE of Spades in the IoT Security Game: A Flexible IPsec Security Profile for Access Control
【24h】

ACE of Spades in the IoT Security Game: A Flexible IPsec Security Profile for Access Control

机译:IoT安全游戏中的黑桃ACE:用于访问控制的灵活IPsec安全配置文件

获取原文

摘要

The Authentication and Authorization for Constrained Environments (ACE) framework provides fine-grained access control in the Internet of Things, where devices are resource-constrained and with limited connectivity. The ACE framework defines separate profiles to specify how exactly entities interact and what security and communication protocols to use. This paper presents the novel ACE IPsec profile, which specifies how a client establishes a secure IPsec channel with a resource server, contextually using the ACE framework to enforce authorized access to remote resources. The profile makes it possible to establish IPsec Security Associations, either through their direct provisioning or through the standard IKEv2 protocol. We provide the first Open Source implementation of the ACE IPsec profile for the Contiki OS and test it on the resource-constrained Zolertia Firefly platform. Our experimental performance evaluation confirms that the IPsec profile and its operating modes are affordable and deployable also on constrained IoT platforms.
机译:受限环境的身份验证和授权(ACE)框架在物联网中提供了细粒度的访问控制,在物联网中,设备受到资源的限制并且连接受限。 ACE框架定义了单独的配置文件,以指定实体之间如何精确交互以及要使用的安全和通信协议。本文介绍了新颖的ACE IPsec配置文件,该配置文件指定了客户端如何与资源服务器建立安全的IPsec通道,并在上下文中使用ACE框架来强制授权对远程资源的访问。通过该配置文件,可以通过IPsec安全关联直接配置或通过标准IKEv2协议来建立IPsec安全关联。我们为Contiki OS提供了ACE IPsec配置文件的第一个开源实现,并在资源受限的Zolertia Firefly平台上对其进行了测试。我们的实验性能评估证实,IPsec配置文件及其操作模式在受约束的IoT平台上价格合理且可部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号